[Ksummit-discuss] [TECH TOPIC] Kernel lockdown and secure boot

Jani Nikula jani.nikula at intel.com
Thu Sep 6 10:21:16 UTC 2018


On Thu, 06 Sep 2018, David Howells <dhowells at redhat.com> wrote:
> Jani Nikula <jani.nikula at intel.com> wrote:
>
>> I guess I'm asking, have you considered an audit log for lockdown
>> blocked access, and if you've rejected the idea, why?
>
> It logs a message to dmesg telling you what caused the rejection.

Ah, good. Looks like this was added at some point, and the user was
running kernel lockdown without this.

Thanks,
Jani.


-- 
Jani Nikula, Intel Open Source Graphics Center


More information about the Ksummit-discuss mailing list